Why You Can't Commit to One AI Provider Anymore with Matthew Sanders - Ep 242
Matthew Sanders is the CISO at Slingshot Aerospace, a company that combines a global sensor network with AI and advanced analytics to help government and commercial customers understand what's happening in space and operate safely. Because of the nature of Slingshot's work, Matthew's biggest concern isn't financially motivated criminals, it's patient nation-state actors willing to linger inside a system undetected for extended periods. He joins the show to talk through prompt injection and model poisoning risk, a striking recent Anthropic threat intelligence report on real world misuse of its own models, and why depending on a single AI provider has become a genuine supply chain risk for organizations in the defense industrial base.
Here’s a glimpse of what you’ll learn:
- Why Matthew says nation-state actors, not financially motivated criminals, are his top concern at Slingshot
- How a recent Anthropic security report revealed threat actors building entire phishing campaigns with minimal prompting
- Why Matthew believes patching no longer means what it used to against AI-discovered zero days
- How Matthew uses Claude daily as a second opinion to catch his own team's missed security settings
- Why defense industrial base policy shifts are forcing security teams away from single-provider AI lock-in
- How Matthew thinks AI assisted testing could finally solve the oldest blocker in patch management
- Why Matthew believes the tide in the AI arms race may finally be shifting toward defenders
In this episode…
Matthew opens by laying out just how much AI has reshaped the security conversation at a company built entirely around AI-driven space intelligence. He walks through the layered risk: prompt injection and model poisoning inside Slingshot's own products, attackers using AI to iterate on attacks faster than ever, and a governance challenge every security leader now faces, trying to understand what tools employees are actually using without slowing the business down. He references a security report Anthropic published just before the recording, detailing how threat actors, including a Russian group targeting Ukraine-based companies, used Claude with only basic instructions to build complete phishing campaigns, compromise hotel Wi-Fi, and create malware targeting iOS, all capability that would have required far more sophistication just a year earlier. He also points back to the MGM breach as a reminder that attackers don't need to target end users at all, since in that case it was a sophisticated IT team itself that got socially engineered.
The conversation turns to where Matthew sees real opportunity rather than just risk. He's candid that watching Darktrace's Secure AI product gives him a genuine glimpse of the future, tools that let security professionals finally see what their own organization is doing with AI in real time, the same visibility advantage attackers have enjoyed for longer than defenders have. He argues the fundamentals, zero trust, least privilege, patching, matter more than ever precisely because AI defense tools don't replace them, and describes using Claude personally as a daily second opinion, feeding in his own SSP and compliance documentation to check whether his team is actually doing what they claim to be doing, catching missed settings in minutes rather than letting them slip through unnoticed. He also sees a major unsolved opportunity in AI-assisted testing, arguing the oldest blocker in patch management, the fear that an update will quietly break something else, could finally be addressed if AI could validate changes before they ship rather than after.
The back half of the episode gets into the operational realities of running security in the defense industrial base during a moment of real policy upheaval. Matthew describes watching organizations get caught flat-footed when a model provider gets restricted for supply chain reasons overnight, forcing a scramble to alternative tools like Cursor or Codex, and argues this volatility means security leaders can no longer commit to a single AI provider the way they once committed to a single cloud vendor. He connects this to the ongoing pause on CMMC Level 2 requirements and the broader shift toward FedRamp's newer, more automation-driven approach, predicting that continuous AI monitoring will eventually replace much of the paperwork-heavy compliance process entirely. He closes on what he calls a genuinely exciting use case: feeding a full SSP into Claude to get instant gap analysis and self-auditing that used to take a human auditor a full week, compressed down to hours.
Resources mentioned in this episode
CyberLynx Website
Matthew Sanders on LinkedIn
Slingshot Aerospace Website
Darktrace Website
Abnormal AI Website
Sponsor for this episode...
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
Check out previous episodes:
Your Internal Network Is No Longer Trusted with Michael Foster - Ep 241
Shared Governance in the Age of AI: Keeping the Institution Safe with Bill Guerrero - Ep 240
Playing With Fire: Securing AI Without Shutting Off the Stove with Nakeea Neischer - Ep 239
Transcript:
Cyber Business Podcast
Matthew Sanders
CISO
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Matthew Sanders, CISO at Slingshot Aerospace. Matthew, welcome to the show.
Matthew Sanders: Hi, glad to be here.
Matthew Connor: Glad to have you. Before we get too far in, a quick word from our sponsors.
Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.
Matthew Connor: And now, back to our show. Matthew, for those who aren't familiar, can you tell us about Slingshot Aerospace and your role there as CISO?
Matthew Sanders: Sure. Slingshot Aerospace provides space operations, intelligence, and autonomy to help government and commercial customers understand what's happening in space and operate safely and effectively. We combine our global sensor network around the world, AI, advanced analytics, and we turn the data we're seeing on orbit into actual insights for our customers. As CISO, my job is to protect these systems and the information our customers rely on to do their mission.
Matthew Connor: You know what, that leads us into the perfect question that's on everybody's mind, securing AI, right, because apparently you're sitting right there in that spot, that seems to be your job from what you just said, you're using AI analytics to create your product, and your job is CISO. So I'm going to let you kick it off with how you go about that, what keeps you up at night, and what helps you sleep well at night, if anything.
Matthew Sanders: Yeah, there are a lot of aspects, AI has really turned the whole security industry on its head, there are so many aspects we have to consider now. We talked about AI in our products, and that's certainly a factor, can there be prompt injection, or poisoning of models, or a confused-deputy problem, getting the model to do something that it, or a human, or a non-AI approach, otherwise wouldn't do. And there's a lot of power, these AI models are going a million tokens a second now, calling out to different systems, doing things so fast that it's not always clear to the operators using them what's happening. And we've seen that with OpenAI, their recent breach report with Hugging Face, where you're not really sure what the AI is doing, is it doing something malicious? That's become super present and clear across the industry lately. In addition to that, we have to worry about attackers using AI to iterate faster on their attacks, it's lowered the bar for doing super sophisticated attacks. Just yesterday, Anthropic came out with their big security report, a bunch of things they'd seen malicious actors doing, using their models, because they were able to bypass the safeguards. Some of them were setting up entire phishing campaigns, compromising hotel Wi-Fi, creating malware that runs on iOS, all with very basic, minimal instructions, here's our target. One of them, they found Russian actors who wanted to target Ukrainian companies, and they set up this whole phishing campaign and malware, and iterated on the malware to evade detection. Just massive capability is enabled now. So that's the attackers, and then within our organizations as well, there's this governance problem, something every security leader is dealing with now, wow, how do I rope this in, how do I understand what's going on? We want to enable the business, as security leaders, we want to enable the business to operate quickly and effectively, we don't want to slow that down, we want to enable more AI, but getting our arms around all the ways AI is being used, and all the tools our employees want to use, are they locking this down with access controls? We don't want to slow them down, but we've got to make sure these models aren't going out and leaking our data somewhere, or getting confused and doing operations they shouldn't be doing, compromising our data. It's a massive effort for security leaders now. There are opportunities too, of course, can we use AI for SOC analysis, tying together all these systems that maybe don't integrate with each other, but AI can call them, use MCPs, call APIs, pull all that information together faster. Going back to the OpenAI and Hugging Face incident, they weren't able to use the frontier models to respond because of guardrails, so they went out and used open-source models, and were able to be more effective in their security incident response because of it. So there are opportunities there, but it always feels like the attackers have the upper hand, at least that's how it's always felt from a security perspective, but now AI has really dialed that up more.
Matthew Connor: You know, that's really interesting. I think we're in a really fascinating time where it's so early, even though it's been just under four years now since OpenAI released ChatGPT, and what we've seen in the progression over these four years has been absolutely fantastic and amazing, and I think what we've seen over the last six months has been truly transformative. I cannot wait for the next six months. And going back to your point of this arms race with the bad guys, this game of cat and mouse, and as the attacker, I think it's really easy to feel like they get the upper hand because they get the first shot. One of the things I get really excited about, when it comes to AI fighting AI, it's cool to see AI in, let's say, the SOC, with SentinelOne and CrowdStrike's use of AI in their AI SIEM and SOC solutions, okay great, that's nice, but that doesn't really help us against the bad guys, that helps the SOC analysts understand things a little faster, which sure helps. But I think what we're starting to see is things like what Darktrace is doing with Secure AI, where you're using AI to be able to see all the ways your organization is using AI, what they're actually doing, what guardrails they have in place when somebody starts putting in proprietary information that maybe they're not supposed to send outside. So I think, and it's such early days, and this is where it gets really exciting, I think this is a glimpse of where AI is going, because I don't think we as security professionals have had all the AI advantages that the bad guys have had, which I think leads to that feeling that they've got the upper hand. I think we're starting to see the tide shift in our favor, when you look at products like that and where that takes us in the future. So I envision a future where cybersecurity professionals get to have insight into what AI is doing in the organization. Right now it's crazy, everybody's running a mile a minute, like never before, in a bunch of different directions, and you want to empower them, you want them to run and make the organization better, at the same time you're trying to secure people who are sprinting down the street half naked, you didn't even put your shoes on, right, and then they're just sprinting, and you're trying to keep them safe. And I think that's where AI is going to help us in the future. I'm an AI optimist, though, so I'll grant you that, but I think that's the sign the industry is starting to see those pain points, the gaps, what we need as security professionals to help secure the organization, and I think we're going to start seeing more of that. But curious what you think.
Matthew Sanders: Yeah, it's the pendulum swinging back the other way, and I think we're at the extreme where it feels like the attackers get, like you said, the first shot, and things are changing. Another important thing you touched on is things are changing so fast, just six, maybe eight months ago, before Mythos and Astra came out, we thought, oh wow, these are cool, and then it leveled up again, and now, going back to that Hugging Face and OpenAI one, I really think that was an important watershed moment, wow, even OpenAI didn't realize their model could do this type of autonomous, end-to-end, attack kill-chain stuff for a cyberattack, and it was eye-opening for the industry to see how fast things are moving. You think back ten years ago, we couldn't have predicted we'd be here with generative AI even five years ago, not even close, it's evolving so fast that I can't even imagine what we're going to see a year from now, I'm hesitant to make any predictions about whether we're going to get the upper hand, or the attackers are going to get the upper hand, anything could happen, it's exciting, like anything could happen, now we're living in this, it's almost like science fiction, I don't know what the possibilities are. So it's very exciting there, but I think an important takeaway is to stay grounded as security leaders, I'm a big believer that we've got to nail the fundamentals. Yes, I want the cool AI tools I don't have today, that are going to enable me to do things beyond just SOC response, going above and beyond that, to what's next. But it's important to remember, now more than ever, the fundamentals are still important, all the stuff we've been talking about for zero trust, making sure you're doing your patching, making sure you're doing least privilege, is more important than ever, that doesn't go away because we get cool AI defense tools, it becomes more important than ever. And one of the things I don't know if everybody's doing yet, and if they're not, I don't know why they aren't, is using tools like Claude, Claude Code, and Claude Cowork, as a security professional, to be able to go and say, hey, here's our SSP, here's our unit, you're in the defense industrial base, so you've got CMMC requirements, to be able to drop it all in and say, here's where we are, first of all, are we actually doing what we're saying we're doing, help me go through this, let's run through it together, and it's amazing, the brilliance, it's like having a team of Microsoft's best security professionals. This didn't exist six months ago, but now it's like having the world's greatest on your side, when it comes to, hey, put together a PowerShell script, they can answer all these questions, do this audit, and pull stuff together at amazing speed and with such brilliance. And now, at least on the good-guy side, with such good guardrails, thought through, here's what you wanted me to do, here's what I'm going to do, and I'm going to keep it to this, but you know, we've got this issue, I know where you're trying to go, what about this issue, and bringing it up, it's amazing.
Matthew Connor: So I think, going back to your point of the fundamentals being so much more important now than ever, I think that's a hundred percent true. And I think that AI, even using Claude on your desktop, should be a kind of go-to tool for every security professional, be like, hey, help me out here, did we set this up right? I don't care if it's checking your own team, because nobody, especially the higher you get, you don't know everything, you don't know all the ins and outs. But you know who does, Claude, Claude gets it real fast, and it's like, yeah, you know what, you've got this, I see where you're going, but you missed this setting, oh crap, that wasn't even on, not saying that's happened, but what do you think of that?
Matthew Sanders: Yeah, definitely, and secure coding practices is a big one too, we've got all these coders writing code with Claude, well, guess what, now we can have a security review every time they write code. So instead of catching it afterward, when we check it in, oh, you didn't sanitize your input, or whatever, now at the time they're coding, we can have Claude, or whatever model is the model du jour, checking that and saying, you didn't sanitize this, you didn't clean this, whatever it is, fixing it right there. So there's definitely power for the good guys to use this as well.
Matthew Connor: For sure. And I think the interesting part is, so you do the fundamentals, what becomes really challenging is balancing, hey, we're doing the fundamentals, but honestly, that's not enough, right? If you rewind ten years, as long as you were up to date on your patches, you could rely on that, be like, yeah, we're up to date, that's solid, I don't have to worry about that wall, it's patched, it's good. Now, patching doesn't mean what it used to mean.
Matthew Sanders: That's right, it doesn't mean what it used to mean, there are zero-days out there, and that's what we've seen in the news with these attacks now, they're coming faster and more furiously than ever, all the time, about these vulnerabilities nobody knew about that have been lurking in our code for years, and now with AI, people are finding them faster than ever. But I do think it's important, because the fundamentals are saying, we're going to do defense in depth, we're not going to count on that one firewall to protect the thing, we're going to count on, if it gets breached, there's another access control policy, or a network firewall policy, or a VPC, or there's something else there, so getting past that first layer doesn't get you access to everything. And that defense in depth is more important than ever now, because of AI finding vulnerabilities left and right.
Matthew Connor: A hundred percent. And I think the challenge is, if a technology exists, which it clearly does, that'll allow you to find zero-days, well, then you use the same thing, it's not like it used to be, where some elite hacker found a zero-day and was exploiting it, they sold it at a premium to some other hackers, and they were exploiting it. Now it's some random person who doesn't know anything about anything, had AI develop this zero-day, and they've got it, or they're renting it, and they're exploiting it. But if AI is creating it, then it's layer after layer, they kind of drill through, with AI, I think that's the fear. And I think the ultimate solution for us good guys is that this is once again where AI fights AI, you have to have AI systems that are monitoring the network, the endpoints, in real time, for abnormal behavior. And we're not even talking about LLMs now, but having machine learning, which is really the way to go, because, let's look at the MGM hack, that was great social engineering, and for most people, that's everybody's Achilles heel, the weakest link, except it wasn't an end user, they basically social-engineered IT, and this was an advanced IT group, it's not like they were a bunch of amateurs, so it's not like you can fault them for it. But what could have happened is, AI can stop that. And when you use things like, I'll just go back to Darktrace again, if you're using their network and endpoint tools, when you see things happen, it sees it in real time, like, wait a sec, I don't even have a profile for this new guy, and he's running around doing stuff that even the most senior, most active admin doesn't do, there, two minutes in and they've been in every system, and they were really fast. And so I think that's the future of defense, that our last layer of defense, after everything else, is we've got to have AI tools that can see things we can't see, because it's happening so fast, and it's like, what is Adobe doing, they've exploited Adobe and now it's encrypting the drive, that's not Adobe's job, let me stop that. I think that's where things have got to go.
Matthew Sanders: Yeah, I think this goes back to what we were talking about earlier, AI in the SOC, and AI is like a SOC analyst, and I think it's very much that, in theory your SIEM tool is operating and looking at rules, but you can't define all the rules, that's always been the challenge of a SIEM tool and SOAR tools, you don't know all the things to look for. And so having that supported with an AI that's going through and can do investigations, like, oh, I'm seeing this weird thing, let me ask some questions, dig into it, pull some more logs and other stuff, and that doesn't line up, and being able to do that at the speed other AIs are operating at, to try to compromise you, is going to be necessary.
Matthew Connor: Yeah. Well, and I think that's what ends up changing the balance of power here, when most organizations are at that level, which obviously isn't now, but hopefully at some point in the not-too-distant future, it's the standard, where it used to be, well, obviously you've got to have antivirus on your computers, even though most viruses weren't much of a threat, the idea of not having antivirus, or not having anti-malware, or not having EDR or MDR, becomes like, what are you doing, you obviously have to have it. So I think when we get to the point where it's so ubiquitous that AI is monitoring everything from the endpoint and the network, it's going to make it so hard for the bad guys, who are currently making a ridiculous amount of money a year with their evil enterprises, I think that's going to start ratcheting the other way, and the money will stop flowing as rapidly. And it's only then that I think we ultimately win that war, because it's a money thing, you'll never get rid of hackers and bad guys altogether, I don't think, but what we've seen since the advent of ransomware, really around the COVID era, ransomware becoming rentable, and all these exploits becoming rentable on the dark web, that industry has exploded, and now the cybercrime industry is many billions of dollars a year, which it didn't used to be, it wasn't so organized. But I think that's where we start winning the war, when the money stops flowing so heavily.
Matthew Sanders: So I want to point out, the threat actors I'm most concerned about, because of the nature of Slingshot's business, aren't after money, it's the nation-state actors, and these are the ones that will compromise the system and linger in it for extended periods of time, not letting you know they're there, waiting. And having AI to be able to move laterally within the system gives them a lot more capability to do that. On the flip side, having AI, like we were just talking about, to do operations and investigations, to be able to identify that and root them out, is going to be really important. But fundamentally, to your point, I think you made a really good analogy there, it used to be like, well, of course you've got to have antivirus, and it's going to come to a point where it's like, of course you've got to have that AI enabled to go do investigations and look at your logs and look for these threat actors. And I think it'll get to a point eventually, like patching, all right, we want to push patches out, but we've got to test them first, so then there's all this, how do we test it and make sure we've tested everything before we push it out, so we don't interrupt operations. I think that's going to be a critical next step too, going and saying, how can I test all this stuff, so I know the patches I'm pushing out aren't going to break things, because a lot of times that's a blocker, that's why patches don't go out the same day they're released, and that gives attackers a lot of opportunity. So being able to step in and leverage AI to speed up the patch cycle, because right now it's being leveraged to speed up the exploit cycle, and we could use it to speed up the patch cycle as well, that's a big enabler for the good guys.
Matthew Connor: I think so. And I think what'll be really helpful is having that AI buffer, to where even if the patch cycle takes longer, and it's a known exploit, okay, but we will still see if that gets exploited, and we will still be able to stop it. So I think ultimately it works both ways there. And I think with manufacturers leveraging AI, and we see it happening already, there are so many more patches now than ever before, at an amazing rate really, and that's great, because we're finding, they're finding more, and that's making the products more secure. And I'm curious your thoughts, I think patching is generally getting better, I mean, we're both old enough to remember the Patch Tuesdays where it was just so bad, you just couldn't update everything, especially on the Microsoft side, it was months before they fixed the major bug that was taking things down, it was rough. I think Microsoft's doing a much better job than they used to on that front, and I don't know if it's just that they've improved their quality control, or if fundamentally the codebase is stronger and better than it was back in the earlier days. Is it the same for you? Before, it was like you really couldn't in good conscience just let it auto-update, you really had to test to see if this one was going to be the one that took down half the organization, and why only half, too, that always got me, same hardware, same software, and it doesn't affect everybody the same way.
Matthew Sanders: No, I think you're right, it is better on Microsoft's side, however, our threat surface is such that, okay, great, that's my endpoints, and I've got Macs, and I've got Linux servers, I've got all this open-source software that gets patched in there, and there are various levels of maturity in the open-source software libraries, some of them are great and have big corporate sponsors, some of them, not so much. So there's always that challenge, because we rely on so many different sources in our supply chain, our software supply chain, and some of them are better at patching than others, and some of them need some help. One partnership we're looking at is Chainguard, and I think they're the only company doing this right now, where they'll back-port open-source software from future or current versions to past versions, so I don't have to go back and do a major version upgrade that breaks my application code, and then my team has to spend a bunch of time patching that. I'm kind of surprised there aren't more operators in that space, maybe with AI in the future we'll see more of that.
Matthew Connor: Yeah, no, that's super cool. And I think part of the challenge is, there are only so many hours in the day, and there's so much to do, and everybody's going so fast. So how do you even, with all the software you have to currently manage, how do you have the time to go through just handling that alone, that's more than a full-time job. So is this something where you're moving toward saying, hey, we're just setting Claude on that, we use Claude, Claude Cowork, Claude Code, and we're going to let it, we're going to give it access, here are the virtual machines, it's all set up, have at it, I want you to run these patches and see what happens, and kind of sign off on it, do you move in that direction, because it's so time-consuming?
Matthew Sanders: Yes, the missing piece there, going back again to testing, like we were talking about testing on imports, but for bespoke software that a company develops internally, I think there needs to be some AI-assisted testing, that seems like a missing piece. Because for a while now, before AI, it was easy to find, Dependabot on GitHub, or others, will go through and say, oh, you're using this old, vulnerable version of this library in your package manager, I can find that and update it to the latest version for you. And then you take that change, and it's too new, it breaks this other code that was relying on that version, and you may not know about it right away, it may boot up and start running, and then you start using it, and things go wrong. That's always been the blocker for fixing things, that's always been the highest hurdle to clear. So getting AI help with more testing, I'm sure somebody's working on it, but that seems like a big market opportunity.
Matthew Connor: Oh, for sure, because just look at how well it does documentation and tracking, I don't know, maybe it's just me.
Matthew Sanders: Oh, totally, and like with some of these open-source, self-hosted browser agents, that's why they blew up, because, all right, I'll look at your screenshots, and I'll go into your web browser and start making all these changes for you, because all I need is a screenshot, I know what's going on on this web page, I can fill in that data and do some tests. So it seems like, I said, somebody's got to be working on that, I haven't looked into it, but it has to be, because that's so important.
Matthew Connor: I mean, I think that's a great example of things that make us better, it's a really great use for AI, and even building that internally, I don't know why you couldn't, especially if you're doing your own development, having that as a separate agent, I keep coming back to Claude, but having that, and making sure the documentation is there, because I think that's part of the challenge, I don't think most developers, most people, are nearly as good at documenting as Claude, as AI is, and I'll stop saying Claude every five seconds, it's because it's right there. But I think AI is so good at it, it's so great at filling those gaps, like the documentation, as you're building that out, it's understanding it, and documenting it, and it's also very human-readable. And so I think even having it go back through old code and understand the dependencies, and what will break with this, it seems like a no-brainer, it's simply a matter of saying, hey, I want you to do this before anything gets pushed, we need to fully document the dependencies, what's going to break with this, why not?
Matthew Sanders: I'm laughing because I just did this earlier today, there's a GitHub repo, an AWS landing-zone accelerator, to stand up CMMC-compliant cloud environments for me, they have a GitHub repository for this, and I'm like, this is weird, where's the Terraform, or the CloudFormation for me, where's the infrastructure-as-code I'm looking at? And I just gave it to Codex, where's the infrastructure's code, it's like, well, it doesn't have it, it generates that when you run this script, and I was like, oh, that wasn't in the readme, I didn't see that, that wasn't clear to me from the readme. But right away I'm like, oh, that's how this thing works, because it just looked at the repo, understood it, did its thing, and gave me a quick summary, exactly what I was looking for. So it's definitely there, for sure. And it's funny though, talking about Claude and reusing Codex, because this is another AI-related thing, AI for our supply chain, and being able to use and trust which tool we're using, because the tool sometimes changes on us in the defense industrial base. A lot of organizations were using Claude, and then the Department of War came out and said, nope, no more Claude, it's a supply chain risk. So some organizations said, let's switch to Cursor, now we don't have the supply-chain problem all the time, we could pick from models, Codex is doing pretty well, it's available from there. And then I think it was last week, OpenAI said, we're not going to provide our models to Codex anymore. So now we're like, we can't do this vendor lock-in anymore, we've got to find solutions where we can pick and choose, and we should, rightfully so, because the models change so quickly. I think for a while Claude was way out in front, and then the other frontier models caught up, the open models are starting to get better, and I think Codex is pretty much on par now, and Astra just came out. The landscape is changing so quickly that we can't be tied to any one AI provider, we've got to just pick tooling, something like a router, something that gives us multiple providers. So that's a security challenge though, from a security aspect, I'm like, okay, if we could commit to Anthropic, and I know they're just dealing with our tokens, I feel okay, that's reducing the risk, but now I've got to worry about, do I have to support multiple providers hosting those models, or one provider? But I want to be able to choose from multiple models, so can I trust those models, are there models I do trust and don't trust, how do I evaluate that? So the supply-chain dependency risk is coming with this, because we now need AI in our supply chain, in our development cycle, there's no getting around that, and so now I have to worry about securing that aspect of it as well.
Matthew Connor: Oh, a hundred percent. I mean, it's one thing for it to be, and we hear this a lot, that AI is going to become this commodity, okay, and this is a great example of that, you have to use the tooling, and whichever model doesn't really matter, but it does, right, it actually does matter which model, because then where's your information going? And I guess that raises the next question, at what point does it become cost-effective, or a necessity, will it become something where we've got to host our own models, we've got to have this under control, and it's got to be central, in that if we decide we want to switch from one to another, fine, but you're now using your own hardware. It's a bit of an investment, isn't it, cheap right now?
Matthew Sanders: It's real cheap when you're just buying the tokens, but if you have to pony up for all the hardware, to be able to run as much, depending on how big the organization is, it's a nice chunk of change.
Matthew Connor: Does it become something where it's a financial or security necessity to have it housed there, or will it be manageable because it's a financial necessity to keep that cost reasonable?
Matthew Sanders: Well, there are a few important factors there, when the hardware is exploding in cost, because of all the data-center builds, you probably don't get the frontier models if you're hosting on your own. And then I think fundamentally, even going back to when the cloud took off, there have been two schools of thought, one is that on-prem is always more secure, I don't trust the cloud provider, and I trust my guys more to operate securely. The other school of thought being, I don't have the resources and budget to do as much security as the big hyperscaler cloud service providers do, actually I trust them more, they have more certifications than I can afford to get, so I actually feel safer with the cloud protecting my data than an on-prem solution. And personally, I fall into the second school of thought, I think the older generation came from on-prem, ran on-prem environments, but for my age group, just when I came about being a security leader, seeing all the certifications I could get in Azure and AWS, and looking at what it would cost me to implement FedRAMP High and everything else in there, I believe it's more cost-effective to implement security in those hyperscale providers than to do proper security on your own, it's a massive difference in cost. So that's my thoughts on that.
Matthew Connor: I think that's the perfect analogy, and I couldn't agree more, and you see it, it's an extreme example, but some of these self-hosted, open-source AI agents are a great example of that, self-hosted, set it up yourself, and the horror stories have been many, people just thinking they'd vibe-code their way right into it, nope. So I'm right there with you, and I think that's the perfect analogy for that, because it's true, we lived through that, and it's very obvious how much better and safer it is when it's hosted by professionals, versus self-hosted. And I know we went to extremes with that example, but it's really hard to compete with that, especially when you start talking about FedRAMP, and FedRAMP High, these are very high bars, and it's difficult. And the same applies for AI, it's not a simple setup, it's not inexpensive hardware, it's very expensive, the amount of hardware you need, the amount of RAM, it becomes very costly, and setting it up securely, good luck, it's not your full-time job, and you're going to get it right? Probably not.
Matthew Sanders: Yeah, it's going to take massive investment to really get it right, and then we deal with a lot of compliance standards, so if you just have to worry about one compliance standard, okay, but now let's say you start getting international customers, and you have to worry about UK Cyber Essentials, you have to worry about Germany's standards, you have to worry about Australia, whoever, they're all coming with these different compliance standards. I could go to the hyperscalers, and guess what, they've already got them. But if I don't, I've got a major GRC exercise, okay, which ones do I meet, which ones don't, let's do the gap analysis, let's do the difference, I've got to implement more controls to show I'm meeting this standard. There's just a strong business case all around to go to the cloud, and I think that's where most of it is. But there are still holdouts who are like, nope, I don't trust that Jeff Bezos isn't going to walk into any AWS data center and pull out that hard drive and look at my data, I've heard that, it sounds silly, but I've heard that.
Matthew Connor: It was FIPS-encrypted anyway, so he'd need the encryption key.
Matthew Sanders: So, I don't trust it, but it's stuff like that. There's another kind of interesting overlap here, because you're talking about the GRC aspect of it too, another big change going on in the defense industrial base right now is with CMMC, and following on a major change to FedRAMP. There was previously talk, with the previous DoD CIO, about changes to the RMF process for classified environments, and how they want to overhaul that, they want more automation, more AI to do scanning. And this is where FedRAMP is going too, with FedRAMP 20x, less process, fewer catalog controls, and more dedicated outcomes. So we're right now in the pause, today is actually day sixty of the sixty-day pause for CMMC Level 2 suspension, they've got, I think, fifteen more days for the DoD CIO to make a recommendation to their Under Secretary. So I don't think any announcement's going to come out today, but maybe in the next two weeks we'll see where they want to go. Personally, my thoughts are it's going to follow what they were talking about with RMF and FedRAMP 20x, catalog controls, more automation, continuous monitoring, AI tools, scan results showing you're reducing risk, so less GRC policy-and-procedure overhead type stuff.
Matthew Connor: Yeah, which is interesting, because it makes me wonder if that was the real push, you always hear that it's cost-prohibitive, and I think that was part of the argument to pause it, to help the smaller businesses, because it was too cost-prohibitive for small business to really participate. I'm not sure that's necessarily true, I think there's a lot of paperwork and policies and procedures that make it cumbersome, time-consuming, and annoying, but they were all kind of important, because all of those are the fundamentals, nothing that was in NIST or CMMC was ever fancy, it was all the fundamentals, and it all is. And so I think it'll be really interesting to see if what you're saying comes out, I could definitely see it saying, hey, here's what you should be leveraging AI for, your automations, your auditing, totally agree. But now how many AI tools is that small business going to have to purchase to accomplish all of this? That's not going to be cheap, would it not have been less expensive to spend the time going through the policies and procedures and getting the fundamentals right? I'm not sure it's necessarily more secure, though I do believe AI will help us with that too, but interesting.
Matthew Sanders: I think GRC in particular is a really great use case for AI, you get an SSP, and it could be dozens, or a hundred-plus pages, and writing that as a human is a lot of work, going through it and understanding it, just reading it as a human is a lot. Having AI answer specific questions about it that you're interested in, or summarize it, or say, hey, identify non-conformance or risk points, and then hooking that up to the ability to go and query the live environment, so much stuff that took months to accomplish could be done in hours or less with that AI assistance. So GRC is a great use case, yes there's a cost to it, but I think it significantly lowers the cost compared to having a human do all that manually.
Matthew Connor: I couldn't agree more, and on that, just the simple auditing end of it, even the drafting, the reviewing, it's brutal, because you're right, it's often a hundred-plus pages for the SSP, it's not a lot of fun, even reading through the compliance paperwork with the regulations, that's nobody's favorite thing to read, and if it is your favorite thing, congratulations, you found your, I don't know, good for you, but it's really tough reading. But that's perfect for AI, and so marrying those two up, hey, first of all, how's our current SSP, oh, it's garbage, thanks, how do we make it better? And then going through and self-auditing and being prepared, I think that's it. And then for an auditor to come in, instead of it being that traditional week or whatever, of going through everything painfully, feed it all into the machine, have it go through and check, how long does that take, now we're talking hours, not just one auditor's time, give it read access to some of your systems so it can go in and validate things, and you could wrap that up in a day if you've got the right connected systems hooked up, easy peasy.
Matthew Sanders: Yeah, I think we've solved it, I'm not sure who we have to tell, but we need to spread the word, I think we've solved it, we just need to bundle it up, ship it off, we've done it, I think.
Matthew Connor: Yeah, that's freaking awesome. Matthew, this has been so much fun, I could do this all day. But before we go, can you tell everybody where they can find out more about you and more about Slingshot?
Matthew Sanders: Sure, myself, I'm Matthew Sanders on LinkedIn, however, I've found there are two Matthew Sanders within the Denver area, where I am, so look out for that, you'll just have to look me up with Slingshot, or slingshotaerospace.com, also easy to look up on LinkedIn and the website I just gave.
Matthew Connor: That's awesome, I look forward to finding out if you befriend him, or if you end up offing him. Did other LinkedIn tell you, like, people who look at your profile also look at Matthew Sanders's profile?
Matthew Sanders: I'm like, oh, we need to, we should talk about that, that's awesome.
Matthew Connor: Well, lots of Matthews, lots of Matthews in the world, apparently. So many, fun fact, early on, once the internet came out, it was actually on Skype where I found the first other Matthew Connor, I was like, hey, he was this kid in the UK, and then Facebook came out and there were like four hundred of us, we all started befriending each other, I'm friends with like four hundred, and then it was, you've got a birthday, literally every day, somebody named Matthew Connor's got a birthday, it got real annoying. But unlike the Matthew Sanders situation, I somehow doubt there are four hundred of you, but apparently I'm like a John Smith over here, I had no idea until the internet told me.
Matthew Sanders: Fun fact.
Matthew Connor: But Matthew, thanks again for coming on, and until next time.
Matthew Sanders: Yeah, I really enjoyed it, appreciate it, thank you.







